French DPA Releases New Guidance on Personal Data Security
Time 2 Minute Read

On October 7, 2010, the French Data Protection Authority (the “CNIL”) released its first comprehensive handbook on the security of personal data (the “Guidance”).  The Guidance follows the CNIL’s “10 tips for the security of your information system” issued on October 12, 2009, which were based on the CNIL’s July 21, 1981 recommendations regarding security measures applicable to information systems.

The Guidance reiterates that data controllers have an obligation under French law to take “useful precautions” given the nature of the data and the risks associated with processing the data, to ensure data security and, in particular, prevent any alteration or damage, or access by non-authorized third parties (Article 34 of the French Data Protection Act).  Failure to comply with this requirement is punishable by up to five years imprisonment or a fine of €300,000.

The Guidance provides general recommendations and best practices aimed at assisting data controllers with the implementation of appropriate security measures.  The Guidance is divided into 17 chapters, each dealing with a specific topic about data security, including:

  • Identifying data security risks
  • Authentication of users
  • Educating users on data security risks
  • Security of work stations
  • Security of external devices (e.g. smartphones, laptops, PDAs, flash drives)
  • Backup copies and disaster recovery plans
  • Network maintenance
  • Log files and management of data security breaches
  • Physical security of the premises
  • Security of internal networks
  • Security of servers and software applications
  • Data processors
  • Electronic archiving
  • Disclosure of personal data to third parties
  • Privacy by design
  • Anonymization
  • Encryption

Each chapter provides a summary of the issue, an outline of basic precautions, information on what not to do, and recommendations for going above and beyond. The Guidance also includes a data security evaluation form to help companies assess how well they’re protecting personal data.

For more information, read the CNIL’s Guidance (in French).

Update: On November 4, 2011, the CNIL released the English version of the Guidance.

You May Also Be Interested In

Time 3 Minute Read

Indiana’s comprehensive consumer privacy law, the Indiana Consumer Data Protection Act, is set to take effect on January 1, 2026. In advance of the law’s effective date, the Indiana Attorney General’s Office has published a Consumer Bill of Rights that provides guidance to both consumers and businesses.

Time 1 Minute Read

On October 14, 2025, the European Data Protection Board announced that its fifth coordinated enforcement action will focus on compliance with the transparency and information requirements under the GDPR.

Time 3 Minute Read

On September 4, 2025, the Court of Justice of the European Union issued a significant decision in the case EDPS v SRB C-413/23 P regarding pseudonymized data, holding that whether pseudonymized data constitutes personal data is a fact-specific determination.

Time 4 Minute Read

The Colorado Department of Law recently issued a Notice of Proposed Rulemaking with proposed draft amendments to the Colorado Privacy Act rules.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page